NAT/ 路由 模式安装配置举例:到互联网的多重连接

 

按以下步骤添加冗余的默认策略:

1

进入 防火墙 > 策略 > 内部 ->DMZ。

2

单击新建。

 

3

根据默认策略配置相应的策略。

 

内部 _ 全部

 

目的

DMZ_ 全部

 

任务计划

 

服务

任意

 

动作

 

NAT

NAT。

4 单击确定以保存您所做的修改。

添加更多的防火墙策略

大多数情况下您的防火墙配置中不只包含了默认的策略。然而,创建冗余策略将使 得防火墙的配置变得更加复杂。为了将 FortiGate 设备配置为使用到互联网的多重连 接,您必须为从内部网络到每个连接到互联网的接口的连接方式创建双重的策略。而 且,您添加了冗余策略后,还需要在两个策略列表中将他们按照相同的顺序排列。

限制到单一互联网连接的访问

在某些情况下,您可能希望将一些通讯限制为仅能通过一个到互联网的线路进行连 接。例如,在 第 40 页 图 9 所示的拓扑结构中,该机构可能希望只有通过 ISP1 的到 SMTP 服务器可以连接到他们的邮件服务器。为此,您需要为 SMTP 连接添加一个内部 - > 外部防火墙策略。因为没有添加冗余策略,来自内部网络的 SMTP 通讯总是连接到 ISP1。如果到 ISP1 的连接失败,SMTP 连接就无法建立。

FortiGate-500 安装和配置指南

45

Page 57
Image 57
Fortinet 500 manual 添加更多的防火墙策略, 限制到单一互联网连接的访问, 单击新建。 根据默认策略配置相应的策略。

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.